Junglewise Threat Intelligence

CVE-2024-23113: Fortinet Multiple Products Format String Vulnerability

CVE-2024-23113 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-09

Technologies: Fortinet FortiProxy, Fortinet Fortipam, Fortinet FortiOS, Apple Multiple Products, Fortinet FortiSwitchManager. Vendors: Fortinet, Apple.

Executive brief

A format string vulnerability in multiple Fortinet products allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted packets. The flaw stems from the use of externally-controlled format strings in several versions of FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager.

Affected products

  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
  • Fortinet FortiPAM 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
  • Fortinet FortiSwitchManager 7.2.0 through 7.2.3, 7.0.0 through 7.0.3

Timeline

  • 2024-02-15: disclosed: Initial NVD publication date
  • 2024-10-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-09: advisory: CISA advisory published

Related threats